8 out of 10 Banks HATE This One Weird 3SKey RCE
TL;DR. SConnect – 1M+ users, an extension middleware+native host for authentication with eIDs, 3SKeys and other hardware signing tokens had a drive-by RCE which enabled any site or iframe a user saw to silently download and execute a dll due to a poor hand-rolled implementation of RSA-2048 token validation, enabling a use of uninitialized memory validation bypass which enabled “plugins” (DLLs) to be loaded. v2.16.0.0 of the extension and native host is vulnerable. CVE-2026-18397. CVSS 9.4. submitted by /u/acorn222 [link] [comments]Technical Information Security Content & DiscussionRead More